Crypto & Web3·Aug 4, 2026

At least 15 attackers exploited Coldcard vulnerability: Galaxy

Galaxy said that at least 15 different attackers have exploited the Coldcard vulnerability, which may have been avoided with just $2 worth of AI hardening, according to Dragonfly’s managing partner.

Cointelegraph2 min readVerified
At least 15 attackers exploited Coldcard vulnerability: Galaxy
Image · Cointelegraph
The gist
4-point summary · 1 min

Galaxy said that at least 15 different attackers have exploited the Coldcard vulnerability, which may have been avoided with just $2 worth of AI hardening, according to Dragonfly’s managing partner.

  • The company also identified a suspected fourth wave that could bring total losses to about $130 million in Bitcoin (BTC).The ongoing attack reignited debate about the security of cold storage wallets and whether users are safer by holding their own Bitcoin.
  • He said:“The claim that AI found it in 2 mins came from a pseudonymous Reddit user who scanned the code after the vulnerability had already become public.
  • Cointelegraph is committed to independent, transparent journalism.
  • This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information.
$2$100 million$130 million
In this article

At least 15 different attackers have exploited the Coldcard vulnerability, according to Galaxy Digital’s head of research, Alex Thorn, citing new victim reports received since the incident.Thorn said Tuesday that the victim reports helped the company label new attackers that would have gone undiscovered, as the nature of the exploit was different from a hack on a centralized exchange. “Due to one single victim’s report of less than 1 BTC stolen, we identified a new attack with 12 BTC siphoned from 126 addresses,” Thorn wrote in a Tuesday X post.The estimated losses from the Coldcard exploit have grown to $100 million across three confirmed attack waves, according to Galaxy Research. The company also identified a suspected fourth wave that could bring total losses to about $130 million in Bitcoin (BTC).The ongoing attack reignited debate about the security of cold storage wallets and whether users are safer by holding their own Bitcoin. $2 worth of AI hardening could have prevented the exploit: Dragonfly partnerRoughly “$2 of AI hardening” could have prevented the Coldcard exploit, wrote Dragonfly managing partner Haseeb Qureshi, citing social media reports that some AI models rediscovered the vulnerability that led to the attack in less than 20 minutes.Qureshi’s remarks came in response to multiple social media users claiming that Claude was able to regenerate the vulnerability in just eight minutes. He argued that these results may have been contaminated by web search and added that open-source AI model GLM 5.2 was able to rediscover the attack in 20 minutes with web access turned off.However, it is unlikely that AI models would have independently discovered this vulnerability before it was made public, crypto analytics platform Tokenomist’s data lead, Tatsapat Saerejittima, told Cointelegraph. He said:“The claim that AI found it in 2 mins came from a pseudonymous Reddit user who scanned the code after the vulnerability had already become public. There was no blind test, no documented methodology, and no assessment of the model’s false-positive rate.” Related: AI has not triggered DeFi ‘hackpocalypse,’ Dragonfly partner saysVulnerability seen in private key setupCrypto research company Castle Labs’ co-founder, Francesco, said that the growing capabilities of AI models are drastically reducing the cost and time it takes to discover new cryptocurrency vulnerabilities, but added that Coldcard’s private key may have played a role in the vulnerability. Coldcard used a “level of private key entropy (40 bits) much lower than the standard adopted by other wallets (a 12-word seed is 128 bits), a result of a firmware bug, making the job easier,” he told Cointelegraph.Francesco, who asked that Cointelegraph not use his last name, said he expects the cost of bug discovery to continue decreasing as AI models gain more capabilities and become more prominent in both cybersecurity and exploits.Magazine: Does Botanix’s failure prove Bitcoiners don’t care about DeFi? Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

Integrity note  ·  Xela does not rewrite or paraphrase article content. The excerpt above is the source publication's own words, sanitized for display. For the full piece — including any quotes, charts, or images — read it at Cointelegraph. Xela's rewritten version is off for this story, so there's no editorial angle attached — you're getting the source's reporting unfiltered. When the rewrite is on, we add a What this means block underneath with the operator/trader takeaway.

What people are saying

Discussion

Hot takes

0/280

Loading takes…

Comments

Discussion · 0

Sign in to comment, like, and save articles.

Sign in

Loading comments…

Newsletter

Track crypto & web3 every morning.

Daily digest tuned to this beat. The 5 stories most worth your time. Unsubscribe anytime.